there are templates available from team cymru on how best to protect your name server....bind9 has the ability to blackhole queries from certain IP address blocks. all you need to do is create an ACL, call it "bogon" and list the IP address ranges in there that you want blackholed.....then put the blackhole option and .....

No Richard, that is not my build... i happen to be secondary for .UG, i cannot afford to blackhole IP address ranges, even if not assigned...my routers take care of the private address block...

http://www.cymru.com/Documents/secure-bind-template.html
http://www.cymru.com/Documents/secure-bind-template-22.html

you should find the bogon list explained in those


mike
_______________________________________________
LUG mailing list
[email protected]
http://kym.net/mailman/listinfo/lug
%LUG is generously hosted by INFOCOM http://www.infocom.co.ug/

The above comments and data are owned by whoever posted them (including 
attachments if any). The List's Host is not responsible for them in any way.
---------------------------------------

Reply via email to